Privacy Policy
Effective [EFFECTIVE_DATE]. Contact: support@twinbridge.io
In one paragraph
TwinBridge copies product, stock and order information between your Shopify store and your eBay seller account. To do that it stores the minimum needed to keep both sides in step. It does not store your customers' personal data — not names, not addresses, not email addresses, not payment details. If you only read one section, read What we do not store.
What we access, and why
TwinBridge asks Shopify for these permissions. Each one exists for a stated reason; we do not request anything we do not use.
| Shopify permission | Why it is needed |
|---|---|
read_products | read titles, variants, options and metafields to build the eBay listing |
read_inventory, write_inventory | read stock to push to eBay; write stock back when an eBay order is imported |
read_locations | know which locations hold stock |
write_orders | create the Shopify order that corresponds to an eBay sale |
read_fulfillments | read fulfilment details so they can be carried back to the eBay order |
On the eBay side TwinBridge requests exactly three scopes — inventory, account settings and fulfilments (sell.inventory, sell.account, sell.fulfillment). It does not request, and cannot read, your eBay account holder's personal details.
What we store
- Shop identity: your
myshopify.comdomain and the internal identifier Shopify assigns to your shop. That is all we keep about who you are. Your shop name and contact email are not stored — when we need to email you, they are read from Shopify at that moment and used for that message only. - Product and listing links: SKU, eBay listing and offer identifiers, the values we last sent and the values we last read back. This is what makes "synced" mean verified rather than request sent.
- Order skeletons: the eBay order identifier, the matching Shopify order identifier, and the state of the import. No buyer names, addresses, emails or payment data — and no line items either.
- Access tokens for Shopify and eBay, stored encrypted (see Security).
- Operational records: what was synchronised and when, what failed and why, and the emails we sent you. These let support answer a question with a fact from the system instead of asking you for screenshots.
What we do not store
We do not store buyer personal data. When an eBay order arrives, TwinBridge reads it, creates the matching Shopify order, and keeps only the two order identifiers and the state of the import. The line items live in Shopify, where you already keep them — not in a second copy here.
This is a property of how the app is built, not a promise about our intentions. It is also why, when Shopify sends us a customers/redact request, the honest answer is that there is nothing to delete — we confirm the request and record it for audit.
We do not sell data. We do not share it with advertisers. We do not use it to train machine-learning models.
Who else sees the data
Data is shared only with parties that are necessary to run the service:
| Recipient | What they receive | Where |
|---|---|---|
| Shopify | requests to read and write your store data | your store's region |
| eBay | listing, inventory and fulfilment data for your own seller account | eBay's infrastructure |
| Scaleway (hosting, database, key management) | everything the app stores | Paris and Amsterdam, EU |
| Scaleway Transactional Email | notification emails we send you | EU |
| Backblaze B2 | encrypted database backups | EU |
Everything we run ourselves is inside the European Union — hosting, database, key management, backups and outgoing email. Shopify and eBay are not ours: Shopify processes your store data in the region of your store, and eBay on its own infrastructure, each under its own terms.
Security
- Access tokens are encrypted with envelope encryption — each token is sealed with a data key, and that data key is itself sealed by a key held in a managed key service. Plain tokens are never written to disk or to logs.
- Each shop's data is isolated at the database level, so one shop's queries cannot reach another shop's rows.
- Logs are written through an allow-list: only listed fields are recorded, and the output is scrubbed for tokens, keys and email addresses before it is stored. Product names and SKUs are deliberately kept out of error fields.
- Backups are encrypted before they leave the server.
No system is beyond compromise, and we will not claim otherwise. What we can say is what the design does and does not put at risk.
Deleting your data
- Uninstall the app. Your subscription is cancelled immediately and access tokens are destroyed at once.
- Full deletion follows automatically. Shopify sends a shop redaction request 48 hours after uninstall, and everything we hold for your shop is deleted then.
- You can ask sooner. Write to support@twinbridge.io and we will delete it on request rather than waiting for the 48-hour signal.
Your rights
If you are in the European Union, the GDPR gives you the right to access, correct, export, restrict and erase your data, and to complain to your national data protection authority. Write to support@twinbridge.io; requests are answered within 30 days, usually far sooner.
If a shopper contacts you about their data, note that TwinBridge does not hold it — see What we do not store.
Changes
If this policy changes in a way that affects what we store or who receives it, we will email the address Shopify holds for your shop before the change takes effect. Editorial corrections are published without notice, and the effective date at the top is updated.
Contact
support@twinbridge.io — answered by the developer who built the app, within a few hours, every day. Not a 24/7 desk, and we would rather say so than promise one.